CVE-2015-8917: Null Pointer Dereference
Published Sep 20, 2016
·Updated
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
Affected Software
8 affected componentsFixes available
debian/libarchive
3.4.3-2+deb11u13.6.2-1+deb12u13.7.4-1
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Libarchive libarchive<=3.1.901a
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8917?
CVE-2015-8917 is rated as a moderate severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2015-8917?
To fix CVE-2015-8917, update libarchive to version 3.2.0 or later.
3
What can exploit CVE-2015-8917?
CVE-2015-8917 can be exploited by remote attackers using an invalid character in the name of a cab file.
4
Which software is affected by CVE-2015-8917?
CVE-2015-8917 affects libarchive versions prior to 3.2.0.
5
What type of vulnerability is CVE-2015-8917?
CVE-2015-8917 is a denial of service vulnerability caused by a NULL pointer dereference.